CVE-2003-0500
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.
- Affected products
- Postgresql, Proftpd
- Proftpd Project Proftpd
- = 1.2.9_rc1
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 18.3% (97th percentile)
- NVD status
- Modified
- Published
- 2003-07-04
CVE-2003-0500 at NVD
1 known exploit for CVE-2003-0500
Proof-of-concept code and exploit modules indexed by Sploitus